Know exactly who is calling your API.
One request tells you whether the visitor is a real person on a residential connection, a company network, a crawler, or someone hiding behind Tor, a VPN, a proxy or a relay. Then it returns the decision: allow or deny.
Default deny, with a reason
Every lookup returns an identity and an explicit decision. Unidentifiable traffic is refused — that is where proxies and VPNs hide.
One endpoint, under 40 milliseconds
Keys are bound to your website and carry their own country and bot policy, so each of your integrations can be configured separately.
# One call. Bearer key + your site's Origin. curl https://kajodo.com/api/v1/lookup?ip=90.2.150.7 \ -H "Authorization: Bearer 1|xxxx" \ -H "Origin: https://shop.example.com"
{
"country": "France",
"country_code": "FR",
"city": "Paris",
"identity": {
"type": "simple_visitor"
},
"access": {
"decision": "allow"
}
}
Built for enforcement, not just reports
Keys bound to your site
A key only answers requests carrying a matching Origin. A leaked key is useless from another website.
Policy per integration
Sell in Morocco, ship in France: each key carries its own allowed countries and bot list.
Auditable usage
Every call is logged with its key, endpoint, queried IP, status and duration.
No external lookups
Tor exits, relays, crawlers and cloud ranges plus ASN and city data are held locally. No third-party call per request.
Continuously refreshed
Exit lists, relays and ranges refresh on a schedule, so decisions do not go stale.
Honest confidence
Every classification states its evidence and confidence instead of pretending certainty.
Country and city in every answer
You also get the visitor's country, city and ASN, so you can show prices, stock and offers for exactly where they are.
Protect your first endpoint today
Create an account, bind a website, and make your first call in minutes.